CVE-2026-26166 is a double free vulnerability in Windows Shell that permits authorized local users to escalate their privileges on affected systems. The flaw requires local access and moderate technical complexity to exploit, but if successful, grants attackers high-impact capabilities including confidentiality, integrity, and availability compromises. The vulnerability carries a CVSS 3.1 score of 7.0 (HIGH) with a local attack vector and low privilege requirement, indicating that authenticated users with standard permissions can trigger the exploit. The associated EPSS score of 0.00045 suggests minimal real-world exploitation probability relative to the broader CVE ecosystem, placing this vulnerability below the 0.139th percentile for exploitation likelihood. Current exploitation indicators remain limited, with no active KEV listing and an inactive status on threat hot lists, indicating no widespread or coordinated attacks have been observed. The FAUCET risk score of 37.0/100 reflects moderate concern, though the lack of public exploit code availability and minimal community attention suggest this remains a localized threat requiring proactive patching rather than emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.22631.6936CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.22631.6936CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* | ||
< 10.0.26100.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* | ||
< 10.0.26200.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.